This privacy policy describes how your personal data is collected, used and protected when you use the Island Living SXM website and when you make a booking. It is drafted in accordance with the EU General Data Protection Regulation 2016/679 (“GDPR”).
1.Data Controller
The data controller for personal data collected through this website is:
- Name: Island Living SXM — operated by Chenille Investments Ltd
- Address: Hunkins Waterfront Plaza, Suite 556, Mainstreet, Charlestown, Saint Kitts and Nevis
- Contact email: admin@islandlivingsxm.com
- Phone / WhatsApp: +1 (514) 947-6100
For any question relating to your personal data, please contact us at the email address above.
2.Personal data collected
When you make a booking, we collect the following data:
- full name of the lead guest;
- email address;
- dates of stay and number of guests;
- villa booked and total amount of the reservation;
- chosen payment method (PayPal or bank transfer);
- PayPal transaction reference or internal banking identifier (depending on the payment method);
- language preference selected on the website (FR or EN);
- any free-form message you send us during booking or via the contact form.
When you simply visit the website, we also automatically collect technical data: IP address, browser type, pages visited, dates and duration of visits. This data is strictly necessary for the proper operation and security of the site (fraud prevention, error logs).
We never collect: your full credit card number, your card security code (CVV), or any sensitive banking information. This data is processed directly by PayPal or by your bank, without transiting through or being stored on our servers.
3.Purposes and legal basis
Your data is processed for the following purposes:
- Booking management — creation, confirmation, follow-up and possible cancellation. Legal basis: contract performance (Art. 6.1.b GDPR).
- Sending confirmation and information emails related to your stay. Legal basis: contract performance (Art. 6.1.b GDPR).
- Invoicing and accounting / tax obligations. Legal basis: legal obligation (Art. 6.1.c GDPR).
- Fraud prevention and site security (payment amount verification, technical logs). Legal basis: legitimate interest (Art. 6.1.f GDPR).
- Responding to your contact requests via the form or by email. Legal basis: legitimate interest (Art. 6.1.f GDPR).
We do not use your data for commercial purposes (newsletters, marketing, etc.) without your prior explicit consent.
4.Data recipients
Your data is accessible to authorised personnel at Island Living SXM (the owner and her technical administrator if applicable).
It is also transmitted to the following technical providers, strictly necessary for the operation of the site and the management of your booking:
- Vercel Inc. (United States) — website hosting;
- Supabase Inc. (United States) — secure database storing the bookings;
- PayPal Holdings Inc. (United States) — PayPal payment processing (only if you choose PayPal);
- Resend Inc. (United States) — transactional email delivery service (booking confirmations);
- RBC Royal Bank NV and correspondent banks — only in the event of a bank transfer (the bank details appear in the wire instructions email).
None of your data is transferred, sold or rented to third parties for commercial purposes.
5.Transfers outside the European Union
Some of our technical providers (Vercel, Supabase, PayPal, Resend) are located in the United States. These transfers are governed by:
- the Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR);
- and/or certification under the EU-U.S. Data Privacy Framework where the provider is listed.
These mechanisms guarantee a level of protection of your data equivalent to that provided by the GDPR in Europe.
6.Retention period
Your data is retained:
- Booking data (name, email, dates, villa, amounts): for 3 years from the end of the stay, corresponding to the contractual limitation period.
- Accounting documents and invoices: for 10 years, in accordance with legal accounting obligations.
- Technical and IP logs: for 12 months maximum, for security and fraud prevention purposes.
- Contact messages: for 2 years from the last exchange.
Beyond these periods, your data is either deleted or irreversibly anonymised.
7.Your rights
In accordance with the GDPR, you have the following rights at any time:
- Right of access to the data we hold about you;
- Right of rectification of inaccurate data;
- Right to erasure (“right to be forgotten”), subject to our legal retention obligations;
- Right to restrict processing;
- Right to data portability in a structured, machine-readable format;
- Right to object to processing on legitimate grounds;
- Right to withdraw your consent at any time, for processing based on this consent (withdrawal does not affect the lawfulness of prior processing).
To exercise these rights, please send an email to admin@islandlivingsxm.com specifying the subject of your request. We will respond within a maximum period of 30 days. Proof of identity may be requested to verify your identity.
If you disagree with our processing, you may lodge a complaint with the competent supervisory authority: CNIL in France (cnil.fr), or any other supervisory authority of your country of residence in the EU.
8.Cookies
The Island Living SXM website uses only strictly necessary cookies for its proper functioning and currently uses no analytics or advertising cookies.
The cookies set on your browser are:
- NEXT_LOCALE: stores your language choice (FR or EN), valid 13 months;
- admin_token, sb-access-token, sb-refresh-token: secure session cookies (httpOnly), intended only for site administrators when they log in to the private area.
As these cookies are strictly necessary (Article 82 of the French Data Protection Act), no prior consent is required. You may nevertheless delete them at any time via your browser settings.
9.Data security
We implement appropriate technical and organisational measures to protect your data against any unauthorised access, alteration, disclosure or destruction:
- TLS / HTTPS encryption of all communications with the site;
- secure session cookies (httpOnly, SameSite);
- encrypted administrator password and restricted access;
- isolated database and strict access policies (RLS) at Supabase;
- payment processing delegated to PayPal, PCI-DSS certified: no sensitive banking data transits through or is stored on our servers.
10.Changes to this policy
We may modify this policy to adapt it to changes in our services or applicable regulations. Any substantive change will be communicated to you by email on your next booking, and the “last updated” date displayed at the top of this page will be modified accordingly.
We invite you to consult this policy regularly to stay informed about how we protect your data.